Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-6303

Опубликовано: 25 июн. 2024
Источник: nvd
CVSS3: 9.9
CVSS3: 8.8
EPSS Низкий

Описание

Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another room, which can be used for privilege escalation by moving the #admins alias to a room which they control, allowing them to run commands resetting passwords, siging json with the server's key, deactivating users, and more

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:conduit:conduit:*:*:*:*:*:*:*:*
Версия до 0.8.0 (исключая)

EPSS

Процентиль: 57%
0.00357
Низкий

9.9 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-862
CWE-862

Связанные уязвимости

CVSS3: 9.9
github
больше 1 года назад

Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another room, which can be used for privilege escalation by moving the #admins alias to a room which they control, allowing them to run commands resetting passwords, siging json with the server's key, deactivating users, and more

EPSS

Процентиль: 57%
0.00357
Низкий

9.9 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-862
CWE-862